1 |
commit: d3276d612490b7dad0eb6731d49ded1e0761c5ef |
2 |
Author: Laurent Bigonville <bigon <AT> bigon <DOT> be> |
3 |
AuthorDate: Thu Jan 7 15:46:49 2016 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Jan 30 17:16:56 2016 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=d3276d61 |
7 |
|
8 |
Label Xorg server binary correctly on Debian |
9 |
|
10 |
On Debian, /usr/bin/Xorg is only a shell script which executes |
11 |
/usr/lib/xorg/Xorg.wrap, which is a SUID binary wrapper around |
12 |
/usr/lib/xorg/Xorg. |
13 |
|
14 |
policy/modules/services/xserver.fc | 2 ++ |
15 |
1 file changed, 2 insertions(+) |
16 |
|
17 |
diff --git a/policy/modules/services/xserver.fc b/policy/modules/services/xserver.fc |
18 |
index 619bb9f..a531dba 100644 |
19 |
--- a/policy/modules/services/xserver.fc |
20 |
+++ b/policy/modules/services/xserver.fc |
21 |
@@ -71,6 +71,8 @@ HOME_DIR/\.Xauthority.* -- gen_context(system_u:object_r:xauth_home_t,s0) |
22 |
/usr/bin/Xorg -- gen_context(system_u:object_r:xserver_exec_t,s0) |
23 |
|
24 |
/usr/lib/qt-.*/etc/settings(/.*)? gen_context(system_u:object_r:xdm_var_run_t,s0) |
25 |
+/usr/lib/xorg/Xorg -- gen_context(system_u:object_r:xserver_exec_t,s0) |
26 |
+/usr/lib/xorg/Xorg\.wrap -- gen_context(system_u:object_r:xserver_exec_t,s0) |
27 |
/usr/lib/xorg-server/Xorg -- gen_context(system_u:object_r:xserver_exec_t,s0) |
28 |
/usr/lib/xorg-server/Xorg\.wrap -- gen_context(system_u:object_r:xserver_exec_t,s0) |